Tips for Ethical Hackers

Part of the Hacking For Dummies Cheat Sheet

As an information security professional, you may perform ethical hacking against a customer’s systems or your own. For your own safety follow these rules for success no matter who your ultimate client is:

  • Get permission in writing to perform your tests.

  • Set goals and develop a plan before you get started.

  • Have access to the right tools for the tasks at hand.

  • Test at a time that’s best for the business.

  • Understand that it’s not possible to detect every security vulnerability.

  • Study malicious hacker and rogue insider behaviors and tactics. The more you know about how the bad guys work, the better you’ll be at testing your systems for security vulnerabilities.

  • Don’t overlook nontechnical security issues; they are often exploited first.

  • Make sure that all your testing is aboveboard.

  • Treat other people’s confidential information at least as well as you would treat your own.

  • Bring vulnerabilities you find to the attention of management and implement the appropriate countermeasures.

  • Don’t treat every vulnerability discovered in the same manner. Not all weaknesses are bad. Evaluate the context of the issues found before you declare that the sky is falling.

  • Show management and customers that ethical hacking is good business. Ethical hacking is an investment to meet business goals. Make it clear that you’re not playing silly hacker games.

Comments (0)

Leave a Reply


Post Comment

SERIES
Hacking For Dummies Cheat Sheet

Grab a free widget and we'll bring interesting & helpful tips to your favorite personal page each day

Sign Up for RSS Feeds

Computers & Software

Inside Dummies.com